← ALL ADVISORIES

CRITICAL BYTERAY-2026-0212Disclosed

U-Boot — Out-of-Bounds Write in IP Fragment Reassembly

U-Boot's IP fragment reassembly writes into the reassembly buffer using attacker-controlled fragment offset and length without adequate bounds checking, so a crafted fragmented packet sent during netboot writes out of bounds and corrupts adjacent memory.

Advisory
BYTERAY-2026-0212
CVE
CVE-2026-71971
CWE
CWE-787
CVSS
8.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N); 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
Vendor
U-Boot
Product
U-Boot
Reported
2026-07-28
Disclosure
2026-09-29
Affected
U-Boot before 2026.10-rc3, builds with CONFIG_IP_DEFRAG enabled
Fixed in
2026.10-rc3 (commit 04ca915d5bf39dda5d1bce62d04d2b59d293c5b9)

Executive Summary

When U-Boot is built with CONFIG_IP_DEFRAG and its network stack is active (for example during a netboot), it reassembles fragmented IP packets into a fixed buffer. The reassembly code trusts the fragment offset and length taken from the packet, so an attacker who can send IP packets to the device can drive a write past the end of that buffer. The result is attacker-influenced memory corruption inside the bootloader, reachable over the network with no authentication.

Affected Products and Versions

  • Product: U-Boot, IP fragment reassembly in net/net.c (__net_defragment()).
  • Affected: U-Boot before 2026.10-rc3, in builds with CONFIG_IP_DEFRAG enabled.
  • Fixed: 2026.10-rc3 and later.

Technical Details

__net_defragment() reassembles fragmented IP datagrams into a reassembly buffer. The fragment offset and length are taken from the received packet and used to place fragment data into the buffer without an adequate bounds check. A crafted fragment with a non-zero offset and the More-Fragments flag set places data past the end of the reassembly buffer, an out-of-bounds write of attacker-controlled bytes at an attacker-influenced offset. The path is only present when CONFIG_IP_DEFRAG is enabled.

Reachability and Preconditions

  • The device is running U-Boot networking (for example during a netboot) and is built with CONFIG_IP_DEFRAG.
  • Any host that can send IP packets to the device can reach the parser. No authentication and no user interaction are required.

Impact

An out-of-bounds write that corrupts memory adjacent to the reassembly buffer and crashes the bootloader (denial of service). Because the overflow is an attacker-influenced memory-corruption primitive running inside U-Boot, before the operating system and any verified-boot handoff, it is a plausible path to code execution in the bootloader.

Remediation and Mitigation

Update U-Boot to 2026.10-rc3 or later, which contains commit 04ca915d5bf39dda5d1bce62d04d2b59d293c5b9. Where updating is not immediately possible and IP defragmentation is not required, building without CONFIG_IP_DEFRAG removes the vulnerable path; this disables reassembly of fragmented IP packets.

Timeline

  • 2026-07-28 — Vulnerability public and fix available upstream.
  • 2026.10-rc3 — Fix released (commit 04ca915d5bf39dda5d1bce62d04d2b59d293c5b9).
  • 2026-09-29 — CVE-2026-71971 record published by VulnCheck.

Credits

Discovered and reported by Shahriyar Jalayeri and Mehrun P. Hunter of ByteRay Ltd.

References